Re: To tri-homed, or not to tri-homed... that is the question

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Phillip Windell (_at_.)
Date: 01/31/05


Date: Mon, 31 Jan 2005 16:01:11 -0600


"Hugh G. Johnson" <hughgjohnsonNOT@comcast.net> wrote in message
news:25idnfkK4JN8OGPcRVn-sA@comcast.com...
> We have a Development Web Server we want external clients/developers to be
> able to view and login too, as well as people in our office to publish
too.
> We've tried Web Publishing Rules, but are not happy with the results, so
> we're thinking out side the box (literally.) Would it be foolish to just
> move the web server to just behind the router so it's on the external side

A "development webserver" implies to me that development code is stored on
the server. It would be rather unwise to put the "family jewels" out on the
Internet at all in any kind of situation.

> of the ISA server? We could just port forward say say port 81 from the
> router? Or, is it better to follow MS example of Tri-homed and place a
third
> NIC in the ISA box and run this to the Web server?

Tri-Homed require a separate subnet that is *also* a Public set of
addresses. You can not use Private addresses on the "third-leg". Although
if you combine it with a Back-to-back DMZ you can "fudge" that. But if
already have a Back-to-back DMZ then there isn't much point in the Tri-homed
anyway,...just use the DMZ you already have.

> What we didn't like about Web Publishing is we had to create accounts for
> everyone that wanted to see the web server, and now when we do OWA we have
> to log in twice before we can view exchange or remote workspace.

No you don't. You can publish an Anonymous Website with ISA just fine.
Review the "choices" you made during the Publishing process. You must have
made some wrong choices

-- 
Phillip Windell [MCP, MVP, CCNA]
www.wandtv.com


Relevant Pages

  • Re: Publish in DMZ : How ?
    ... In the internal LAN, on the ISA DMZ ... routable IP addresses on the DMZ segment? ... How do you want your clients to access the web server? ...
    (microsoft.public.isaserver)
  • "Reverse" proxy available. Any need to put web servers in DMZ ?
    ... I have ISA 2004 setup as a workgroup in the DMZ successfully publishing my ... I have a web server that pulls data from a SQL 2000 db. ... Such web server is currently in the "internal" network. ...
    (microsoft.public.security)
  • Re: Seperating the internal network from an extranally exposed Web ser
    ... ISA has the ability to reverse proxy. ... either the DMZ or the Internal network. ... So my initial thought was to setup a web server in the DMZ and allow traffic ... Would it be secure? ...
    (microsoft.public.isa)
  • Re: Use datasource behind a dmz?
    ... The prefered way is to use the "Server Publishing" features of ISA to ... The Web Server on the DMZ would then ... simply treat the ISA as if the ISA was the SQL Server. ... > I have a web server in a dmz. ...
    (microsoft.public.sqlserver.server)
  • Re: Use datasource behind a dmz?
    ... The prefered way is to use the "Server Publishing" features of ISA to ... The Web Server on the DMZ would then ... simply treat the ISA as if the ISA was the SQL Server. ... > I have a web server in a dmz. ...
    (microsoft.public.isa)